Alta Help Center

WPA2/WPA3-Enterprise Wi-Fi Setup

Mike D
Mike D
  • Updated

What This Configuration Does

Enterprise Wi-Fi replaces a shared Wi-Fi password with individual user credentials.

Each client authenticates using a username and password.

Step 1 — Enable RADIUS on Route10

  1. Open your browser and navigate to manage.alta.inc or open the mobile app.
  2. Navigate to Network
  3. Tap or click on the Route10 icon to open the configuration panel
  4. Navigate to Auth
  5. Enable RADIUS by toggling it on
  6. Note the automatically generated shared secret by clicking the eye symbol to unmask it.
  7. Adjust Advanced options only if needed—by default, you do not need to touch them. 
  8. Add users by selecting the `Add User` button
    • Username
    • Password
    • Optional WiFi VLAN
    • Select Save
  9. Select Save if allowed as that means you have unsaved changes. It should be grayed out afterwards/if there are no pending unsaved changes. 

Step 2 — Configure the Wi-Fi Network

  1. Open Settings
  2. Go to WiFi (should open here)
  3. Select `Add new` to create a new WiFi network or select an existing one to change the security type. 
  4. If new, enter your desired network name (SSID)
  5. Under WiFi Security, select Enterprise
  6. Enter:
    1. IP Address — The Route10 IP shown on the Network page
    2. Secret — Must match Route10, found on Auth tab in Route10 config panel
    3. Auth Port — 1812 (default)
    4. Acct Port — 1813 (default)
  7. Configure the remainder of the SSID options as required (optional).
  8. Once done, choose Save

Client Configuration

Windows, macOS, iOS

Most modern operating systems automatically detect Enterprise authentication.

To connect:

  1. Select the Wi-Fi network.
  2. Enter username and password.
  3. Accept the certificate warning on first connection (if prompted).

No additional configuration is typically required.

Android

Many should automatically select the proper defaults, but some Android devices require changing from their OEM defaults. The expected settings are as follows: 

  • EAP method: PEAP
  • Phase 2 authentication: MSCHAPv2
  • CA certificate:  Time On First Use (TOFU) 
  • Identity: Username
  • Password: User password

Field names may vary by device or Android version.
 

Optional VLAN Assignment

If a WiFi VLAN is configured for a user in Route10:

  • The client is automatically placed into that VLAN upon authentication.

If no VLAN is configured:

  • The client remains on the SSID’s default VLAN.

Related to

Was this article helpful?

0 out of 0 found this helpful

Have more questions? Submit a request

Comments

0 comments

Article is closed for comments.